What Happens When a Password Is Checked
The video follows a login attempt from the request boundary to account lookup. It visualizes a stored salt and password-hashing parameters, explains why the server recomputes a deliberately expensive verifier, and shows a generic failure response that avoids unnecessary account enumeration.
After successful verification, the lesson rotates a session identifier and sets appropriate cookie attributes. A final example explains that authentication does not grant access to every resource; each operation still needs authorization. Companion material: security article, login trace, and the OWASP Password Storage Cheat Sheet.
Related articles
Security Follows Data and Authority Across Boundaries
Threat-model a request by tracing sensitive data, user authority, trust boundaries, and the controls that limit abuse.
C++ Concurrency: Threads and Atomics
How std::thread, std::mutex, and std::atomic work, and the race conditions and memory ordering issues they prevent.
Move Semantics and Rvalue References
How std::move and rvalue references eliminate unnecessary copies, and when move constructors are called.
New lessons by email
Get new articles and notes on the systems behind everyday software.
One technical dispatch per week. No noise.
Not started
Sign in to save your learning progress.